Demo Series 14 minMar 4, 2024

How Attack Surface Discovery Strengthens PTaaS Initiatives

Organizations can’t test what they don’t know. Around 69% of orgs have experienced a cyber attack from an unknown or unmanaged asset. Security teams need a more holistic approach to securing the entirety of the asset management lifecycle. How can this issue be addressed? In…

Tim Nordvedt Solutions Architect, Synack

Overview

Organizations can’t test what they don’t know. Around 69% of orgs have experienced a cyber attack from an unknown or unmanaged asset. Security teams need a more holistic approach to securing the entirety of the asset management lifecycle. How can this issue be addressed? In this Cut to the Chase demo, Solutions Architect Tim Nordvedt dives into Synack’s Attack Surface Discovery capabilities. Learn how we’re helping customers identify new vulnerable assets and close gaps between asset discovery and PTaaS programs by reducing the time from discovery, triage, validation and remediation, all on one platform.

Full transcript

Read transcript

Hello, and welcome to today's edition of SYNNEX cut to the chase. My name is Tim Nordvett, and I am one of the solutions architect here at SYNNEX. Our topic today is gonna be discussing how we are helping our customers take a more asset centric view of their security tests and within our platform with things such as asset discovery and asset insights, which we'll touch on in a minute. But the goal is just to better equip our security teams that we're working with to better, more easily secure their organizational assets.

And the main focus of this episode is we're gonna jump into the platform. I'm gonna show you how we're doing that from a technical perspective. But I want to pause for a minute and provide some context as to why Synack and the value that we bring to this space. So I want to take a step back and let's talk about security teams. More specifically, let's look at security teams that are tasked with protecting the external exposure of organizations. They've got a lot of tools in their arsenal, but at a high level, they really have three main work streams that they rely on to help them.

They have pen testing, they have vulnerability management, and they have attack surface management. Well, here at SYNNAC, for the past ten plus years, we've been helping thousands of organizations evolve their penetration tests and vulnerability management work streams, and helping them streamline their vulnerability management lifecycle process by helping them reduce the time from discovery, to triage, to validation, to remediation. So this is an area we have deep experience in. So as we look at industry trends from just in general

watching space and working with our customers, we see a lot of organizations starting to transit transition assets to cloud environments. We see a workforce that used to be centralized is now distributed and decentralized. We see applications being built with serverless architectures and streaming platforms to make them more scalable. We see a lot of organizations starting to implement policies such as zero trust. All this leads to a very ephemeral and dynamic environment, which does have security implications.

We hear stats such as an estimated sixty nine percent of organizations experienced an attack that started with an unknown or unmanaged asset. You know, nine percent of organizations believe that they're monitoring their whole attack surface, which means ninety percent of organizations think they're missing assets when they're monitoring their surface. And from the large organizations we work with, they admit that they're really only pen testing ten percent of the assets due to what they don't know and just the dynamic nature of their surface.

So at SYNNAC, we started looking at this space and trying to see what the underlying problems all were. And what we saw is that in the asset management life cycle, it's a very similar problem set to what we've been, fixing the last ten years in the vulnerability management life cycle. It comes down to an overwhelming number of results, the inability to operationalize those results, and even if you fix those two issues, it's the difficulty of taking the output of those work streams and pulling it into a security testing program. So at SYNNEXT, we decided to take our lessons learned and our experience from

the ten plus years in the vulnerability management space and address that to how can we help the attack surface management space. So our goal is to help companies streamline that asset management lifecycle process by reducing that time from discovery to triage to validation to remediation. We want to empower security teams to reduce cyber risk and just improve overall cyber resilience. In addition to helping companies reduce their exposure concerns, coupling these work streams together allows them

to use ASM workflows to inform security tests in which ultimately allows customers to discover, prioritize, and pen test critical assets. So that's enough of me talking. Let's go and jump into our platform and take a look at how we are actually doing this with our customers. So here we are in the SYNNEXT platform. Let's jump over to our asset tabs. As I mentioned, we're helping our customers take a more asset centric view. When you first come here, you land on the over page.

We'll come back to this in a minute. Our first stop is gonna be discovery because the first thing we need to do is help you discover what your exposure is. So there's two things I wanna highlight on this page. First, seeds and then seeds groups. Seeds can be considered any asset, whether URL or IP based, that is under your management. So it could be your company's top level domain. It could be a series of top level domains. It could be cider block if your company manages an ASN. It could be individual IPs.

It could be a range of IPs, whatever falls within your company's management. And a seed group is how you would structure managing those seeds. In this example that we're sharing today, this demo organization, we set it up by functional groups, but this can be aligned to however your organization manages these assets. So to start a discovery and to start looking to see what your exposure is, it's as simple as creating a new seed group,

and then just add whatever seeds it is that fall within the seed group. And then create and run discovery, and then that kicks off some process on the back end where we're gonna start doing enumeration and looking for any assets that have connection back to the provided seeds. The next stop is to look at what was discovered, and there's a process of confirmation and rejection. So I do want to pause here for a minute and once again go back

to the SYNACK value add. Our goal with this is is not just to do a run a bunch of discovery, toss the results over the fence, and add a bunch of extra work to your team. At SYNNAC, one of our core values when it comes to delivering results to our clients is noise reduction. Security teams and management teams, they have enough noise from all the different tools and scanners. We don't want to add to that. So rather than just running discovery and then sending it over to you, we have a lot of back end processes that looks at a

variety of data points and does our best attempt at attribution to make sure that the results we're providing you, they are truly you can be confident that most of what you're going see is true positive. So it's going to reduce the amount of time it takes to confirm and reject, which assets fall under your management realm. There still is that process of confirmation rejection because some of the discovery may turn up IPs that are like in a cloud shared environment that's hosting one of URLs, but maybe you're not responsible for the IP.

It could be a content delivery network, or it could be like a third party host and provider. So there may be assets connected to your seeds that maybe don't fall under your direct security management. So once you've confirmed or rejected which assets you wanna start getting insights on, then we can come back to the overview page. Because it's one thing to discover the assets. The next step in the process is we want to understand what potential risks those assets pose. So the overview page is going to, at a high level,

kind of shine spotlights on the highest areas of potential risk. There's a lot of different areas we could dive into here. I'll show you a couple of my favorites and kind of where I start when I'm working with customers. One of the top areas of the top vulnerable IP addresses. Now, to go back to what I said initially, one of our goals is we want to help customers reduce that time from discovery to triage, validation, or remediation. Here's where we can start to do that. So top vulnerable IP address is going to start looking at IPs

and cluster as far as what the scanners are pulling back or potential vulnerabilities. So we can quickly drill into here and you'll get the asset details page. Where you can look at the Who is results and try to understand, you know, who's managing this IP, if you need some help with trying to figure out which team to shuffle it to. But where it gets really powerful is you can click in test statuses. So this is linking our security test and data with the asset discovery data, So I can see that this asset is actually in an active assessment right now with our SYNNAC researchers,

some of the best researchers in the world actively triage and validate in this asset. I can flip over to the vulnerabilities tab, and I can see that research has already identified and submitted vulnerabilities on this specific asset. So this is where it gets real powerful when you start to get that peace of mind, because not only did we discover the asset and we identified potential vulnerabilities, we've got the instant confirmation within a few clicks that it's already been triaged and validated by fingertips at keyboards.

We can go back to the overview page and kind of look at another asset. Same thing. I can jump in and see it's under active assessment, so it gives me that peace of mind again. I can look at vulnerabilities and see we've already got a few vulnerabilities that are being submitted and looked at. And if I wanted to, we'll give you that fingerprint information. So if you want to kind of see what it is, the different, services and, software versions thrown up where that's coming from, you can kinda drill into that if you want to. But you can see how it's just a few clicks.

You can start taking those spotlights and doing that validation triage very quickly. There's some other areas we can highlight in here in the bottom left. You know, we're going to overlay all the results with the top CISA CVEs or or Kev's known exploitable vulnerabilities. So from the external exposure, when we find those vulnerabilities, potential vulnerabilities that are linked to sysicas, we'll highlight that for you. Another area I always like to look at is top unique ports. If I go back to my blue team days when I was helping

companies, you know, on the defensive side, You know, in a large organization with hundreds of assets, it's very common to find, like, web ports, you know, twenty two SSH open and such like that. What I like to dig into is what we refer to as long tail analysis. If you've got thousands of assets in an environment and you find one asset with one IP open, from a security perspective, to me that's interesting. Why is there only one asset with one port open? Like, for example, if we're looking here, we see a port eighty one open. That's a little odd to me.

So I can click a button, drill down and see what asset that is. I can see the IP here and I see the fully qualified domain name it's linked to. Again, I can drill in and see the asset details. And I can once again jump over to test statuses. I can see how it is under active assessment. Looks like our research has already identified one potential vulnerability there. So once again, even though at first glance it kind of gives me a little rather red flag up, I can quickly get that peace of mind to know it's under active assessment.

And vice versa, if I was to drill in and I see there's no active assessment right now, it might be warrant me additional investigation. Here's something I need to look in. You either have SYNACT kinda look at this or I can have my team jump in there and take a look at it. So there's a lot of ways you can kinda drill down drill in down here. The overview page, like I said, is just the high level spotlight. The last step I want to take in this demo is kind of looking at our asset list page. This is where you can kind of create your own spotlight and

look at the assets however you want because the asset list is going to give you all the information and a variety of filters of how you can look at this information however you want. Let's say you throw in a provider's filter and your organization has specific hosting environments allowed. You can go through here and you can tag any host environment that's not on your authorized list and you can develop a list of assets that to kind of further triage. Let's say your organization, you want to do a database test,

you can come in here and you can filter on all assets that have a database port open, or maybe you want to filter all assets that have three thousand three and eighty nine, a remote desktop protocol port open. Or maybe you want to filter on test statuses and find any assets that are under active assessment right now or haven't been tested over a year. So you can quickly start to build these different types of asset list, and one, you can either export them out and use them for a variety of different purposes, different tools. But how I mentioned earlier how you can use ASM processes to

inform security testing, you can take these lists that you build, enroll them right into assessments with SYNNAC to have our researchers come on board and look at these assets from that adversarial perspective to ensure that there's no potential exploitable vulnerabilities there. So this is about wraps up everything I wanted to cover today in our demo. Just kind of in closing, just want to mention, you know, our goal with this is not just to be just another ASM offering in the space.

Kind of circling back to what I said initially with the different work streams, our goal is to integrate the ASM processes and workflow into the overall security fabric to help our security teams we're working with create a more holistic approach to securing the entirety of the asset management life cycle. So we look forward to having more conversations with you, answering some of your questions. You know, I'm sure some of you out there have them. So what I would suggest, if you got some questions, if you would like a more in-depth demo to understand how

this can apply to you and how we can help you on this journey, jump over to Synact dot com and reach out to us via the contact us page, and we're looking forward to having some further conversations with you. Thank you. Have a good day.

Speakers

Tim Nordvedt

Synack

Solutions Architect

Next step

Run the test instead of evaluating the idea.

Define a scope, run a Sara AI pentest against it, and see which findings are confirmed as real and exploitable. Then compare that with what your current testing returns.